ss-coding-workflow

Pass

Audited by Gen Agent Trust Hub on Aug 26, 2026

Risk Level: SAFEPROMPT_INJECTION
Full Analysis
  • [INDIRECT_PROMPT_INJECTION]: The skill processes untrusted input from external execution plans and plain-language change instructions.\n- Ingestion points: Processes input from user-provided file paths or text instructions as defined in the Inputs section of SKILL.md.\n- Boundary markers: The skill does not implement specific delimiters or boundary markers to isolate untrusted user data from the agent's internal logic.\n- Capability inventory: The orchestrator invokes sub-skills that possess capabilities for file system modification (ss-coding) and network communication via CLI tools (ss-create-pr).\n- Sanitization: No explicit sanitization or filtering is performed on the input content before it is passed to the coding and delivery sub-skills.
Audit Metadata
Risk Level
SAFE
Analyzed
Aug 26, 2026, 05:56 PM
Security Audit — agent-trust-hub — ss-coding-workflow